May 20, 2012, 12:54:57 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: THC is up and running !
 

 
advertisement:

Pages: [1]
  Print  
Author Topic: HBH JavaScript Hacking 16  (Read 1714 times)
alephone
Newbie
*

Karma: +4/-1
Posts: 7

thc title: 3t3rn4l n00b
thc points: 0
challenges: (0/83)

View Profile
« on: July 24, 2010, 06:47:02 PM »
Share on FacebookFacebook Share

If you read the article on HBH it says that it is 12 characters in length and of the form wordNUMword. Has anyone done this? The fastest bruteforce was said to be under and hour. Unfortunately there are too many false positives.
« Last Edit: July 25, 2010, 12:10:38 PM by zomgwtfbbq » Logged
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« Reply #1 on: July 25, 2010, 12:14:09 PM »
Share on FacebookFacebook Share

Yes the challenge is quite poor, according to my profile I did manage to complete it some time ago.. can't remember the pass anymore though.  Undecided
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
alephone
Newbie
*

Karma: +4/-1
Posts: 7

thc title: 3t3rn4l n00b
thc points: 0
challenges: (0/83)

View Profile
« Reply #2 on: July 25, 2010, 07:38:32 PM »
Share on FacebookFacebook Share

Well, I'm not that interested in the password. I'd like to know how you solved it. I can't brute force this forever.
Logged
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« Reply #3 on: July 26, 2010, 02:28:50 AM »
Share on FacebookFacebook Share

Well, I'm not that interested in the password. I'd like to know how you solved it. I can't brute force this forever.
With the structure you posted in your first post, you have a good start.. combine it with some cUrl magic and that should do it.
Not very elegant but in the end you should have a match.  Grin
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
alephone
Newbie
*

Karma: +4/-1
Posts: 7

thc title: 3t3rn4l n00b
thc points: 0
challenges: (0/83)

View Profile
« Reply #4 on: August 01, 2010, 03:01:36 AM »
Share on FacebookFacebook Share

What do you mean by 'curl magic'? Isn't curl a library for connecting to websites and things like that? Brute forcing the website would take too much time. Just a reminder: we know the checksum calculating algorithm and the checksum. We're supposed to find the password, but there are too many valid strings.

Let's say my wordlist is 'list'. Will I arrive at the string with this logic:
for x in 'list':
 for y in 'all numbers in list':
  for z in 'list':
    if len(x+y+z) == 12, check if the checksum == <required>
Logged
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« Reply #5 on: August 01, 2010, 05:28:48 PM »
Share on FacebookFacebook Share

Yes I mean cUrl, what I meant is that you need to code a script that will hang in there and will post the request to hbh whenever the checksum matches, until you are successful.

And yes your script is fine.
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
Pages: [1]
  Print  
 
Jump to:  


Related Topics
Subject Started by Replies Views Last post
HBH Javascript Hacking 9
Hacker Playground
pr2008 0 893 Last post September 23, 2008, 09:04:49 PM
by pr2008
HBH JavaScript Hacking 6
Hacker Playground
zomgwtfbbq 0 880 Last post September 23, 2008, 03:25:55 PM
by zomgwtfbbq
HBH JavaScript Hacking 5
Hacker Playground
zomgwtfbbq 0 919 Last post September 23, 2008, 02:28:22 PM
by zomgwtfbbq
HBH JavaScript Hacking 2
Hacker Playground
zomgwtfbbq 0 471 Last post September 23, 2008, 01:56:28 PM
by zomgwtfbbq
HBH JavaScript Hacking 1
Hacker Playground
zomgwtfbbq 0 330 Last post September 23, 2008, 01:47:32 PM
by zomgwtfbbq
SMF Board hacked and modded by zomgwtfbekjam aka Rembo from Tools & Design